PT-2026-90231 · Linux · Linux

CVE-2026-89515

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fill in DMA padding bytes in scsi alloc sgtables()
During fuzz testing, the following issue was discovered:
BUG: KMSAN: uninit-value in dma map sg attrs+0x217/0x310 dma map sg attrs+0x217/0x310 dma map sg attrs+0x4a/0x70 ata qc issue+0x9f8/0x1420 ata scsi queuecmd+0x1657/0x1740 ata scsi queuecmd+0x79a/0x920 scsi queue rq+0x4472/0x4f40 blk mq dispatch rq list+0x1cca/0x3ee0 blk mq sched dispatch requests+0x458/0x630 blk mq sched dispatch requests+0x15b/0x340 blk mq run hw queue+0xe5/0x250 blk mq delay run hw queue+0x138/0x780 blk mq run hw queue+0x4bb/0x7e0 blk mq sched insert request+0x2a7/0x4c0 blk execute rq+0x497/0x8a0 sg io+0xbe0/0xe20 scsi ioctl+0x2b36/0x3c60 sr block ioctl+0x319/0x440 blkdev ioctl+0x80f/0xd70 se sys ioctl+0x219/0x420 x64 sys ioctl+0x93/0xe0 x64 sys call+0x1d6c/0x3ad0 do syscall 64+0x4c/0xa0 entry SYSCALL 64 after hwframe+0x6e/0xd8
Uninit was created at: alloc pages+0x5c0/0xc80 alloc pages+0xe0e/0x1050 blk rq map user iov+0x2b77/0x6100 blk rq map user io+0x2fa/0x4d0 sg io+0xad6/0xe20 scsi ioctl+0x2b36/0x3c60 sr block ioctl+0x319/0x440 blkdev ioctl+0x80f/0xd70 se sys ioctl+0x219/0x420 x64 sys ioctl+0x93/0xe0 x64 sys call+0x1d6c/0x3ad0 do syscall 64+0x4c/0xa0 entry SYSCALL 64 after hwframe+0x6e/0xd8
Bytes 14-15 of 16 are uninitialized Memory access of size 16 starts at ffff88800cbdb000
When processing the last unaligned element of the scatterlist, it is supplemented with missing bytes in the amount of pad len. These bytes remain uninitialized, which leads to a problem.
Extend last sg->length by pad len first, then use sg zero buffer() to zero those pad len bytes. sg zero buffer() uses sg miter internally, which correctly handles sg entries spanning multiple pages and padding that crosses a page boundary.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89515

Affected Products

Linux